3 ms·
I've used systems in the past that analyze them server side for similitude with previous passwords of your own (or perhaps only your last password? if that's th
by syrgian 6y ago
I've used systems in the past that analyze them server side for similitude with previous passwords of your own (or perhaps only your last password? if that's the case, requiring current password would be enough, no need to store it in plain text).
They might also want to check it against a list of most used passwords.
- luckylion 6y agoI vaguely remember Microsoft doing this, e.g. "You cannot use your old password and just add a number to it", but I might be mistaken and it may have been only blocking setting the password to a previous one.
- hunter2_ 6y agoAll they'd have to do to safely achieve that is, when you initially set your password to "foo" they will store 11 hashes (foo, foo0, foo1, foo2...). Then when you change your password, it's hash cannot equal any previous hashes.